S3 Bucket Policy and ipv6

Using this: https://support.cloudflare.com/hc/en-us/articles/360037983412-Configuring-an-Amazon-Web-Services-static-site-to-use-Cloudflare as a starting point we have configured s3 buckets for static hosting / cdn many times. However now S3 seems to hate the ipv6 addresses in there. If we take them out then the bucket policy saves fine, but if we leave them in then the bucket policy can not be saved and we get an “access denied” error. Something must have changed somewehere as I can see in some buckets we have the ipv6 is in there but now if we try to resave the policy we get the lovely “Access denied” message.

Anyone else having similar issues? Is it okay to continue only whitelisting the ipv4 CF addresses?

